Hi there,
very dumb question but could not rule out by ourselves
Is it enough to allow ICMP response on WAN interface
set firewall global-options all-ping 'enable'
set firewall global-options broadcast-ping 'disable'
or why need I explicit rules to see ICMP echo?
set firewall ipv4 name svtele_fw_in_213 rule 110 action 'return'
set firewall ipv4 name svtele_fw_in_213 rule 110 description 'Allow ICMP reply'
set firewall ipv4 name svtele_fw_in_213 rule 110 icmp code '0'
set firewall ipv4 name svtele_fw_in_213 rule 110 icmp type '8'
set firewall ipv4 name svtele_fw_in_213 rule 110 protocol 'icmp'
set firewall ipv4 name svtele_fw_in_213 rule 110 state 'established'
set firewall ipv4 name svtele_fw_in_213 rule 110 state 'new'
set firewall ipv4 name svtele_fw_in_213 rule 110 state 'related'
set firewall ipv4 name svtele_fw_in_213 rule 112 action 'return'
set firewall ipv4 name svtele_fw_in_213 rule 112 description 'Accept ICMP Unreachable'
set firewall ipv4 name svtele_fw_in_213 rule 112 icmp type '3'
set firewall ipv4 name svtele_fw_in_213 rule 112 protocol 'icmp'
set firewall ipv4 name svtele_fw_in_213 rule 114 action 'return'
set firewall ipv4 name svtele_fw_in_213 rule 114 description 'Accept ICMP Time-Exceeded'
set firewall ipv4 name svtele_fw_in_213 rule 114 icmp type '11'
set firewall ipv4 name svtele_fw_in_213 rule 114 protocol 'icmp'
Former doesn’t work and blocks echo why latter gives normal ping responses.
Thanks